Data breach
2,844 Separate Data Breaches
- Records
- 231,382,673
- Breach date
- 19 February 2018Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses231,382,673
- Passwords215,844,603
About this breach
In February 2018, a massive collection of nearly 3,000 separate data breach files was found circulating online. According to our investigation team, the archive spans 2,844 individual breach databases and contains 231,382,673 email addresses alongside 215,844,603 passwords, with an estimated date of February 19, 2018. This is not a hack of a single company. It is a compilation: someone gathered breach files from many unrelated sources and packaged them together, a format security researchers commonly call a combo list or credential dump. Reporting by SC Media described the collection as totaling roughly 9 gigabytes, with individual files dating from 2011 through 2018.
The person or group behind the compilation has not been publicly identified, and no one has claimed responsibility. Much of the material appears to have been assembled from older breaches rather than a fresh attack, so the organizations whose users appear in the files are not listed here as a single victim.
What Information Was Compromised?
Our analysis found the following data types in this breach: 231,382,673 email addresses and 215,844,603 passwords.
Security reporting on the collection noted that most of the individual files paired an email address with a password, and that many passwords were stored in plain text, meaning they were not hashed or scrambled. That detail matters, because plain text passwords can be used directly against online accounts without any cracking step.
Not every individual is affected by every type of data listed here.
Because the files came from thousands of different sources, the exact contents vary from file to file. Some records may also be outdated, duplicated, or inaccurate. Verification of such compilations is difficult, and researchers who examined the collection noted that its scale makes record-by-record confirmation impractical.
What Are the Potential Risks for Affected Individuals?
The primary risk from a compilation like this is credential stuffing. Attackers take the email and password pairs in the list and automatically try them on other websites, banking on the fact that many people reuse the same password across multiple accounts. A password leaked in an unrelated 2014 forum breach can still unlock an email account or a shopping site in 2018 or later.
Other risks follow from that:
Account takeover. If you reused a password from an older breach, an attacker may be able to log in to services you still use.
Phishing. With a valid email address in hand, scammers can craft convincing messages that reference real accounts or services.
Further leaks. Once an email account is compromised, attackers can use it to reset passwords on other services, compounding the damage.
Plain text passwords in the collection make these attacks easier, since no decryption is required.
What Should You Do If You Were Affected?
If your email address appears in this compilation, the steps below reduce your risk:
Change passwords on any account where you may have reused the exposed password, starting with email and financial accounts. Your email account is the most important, because it controls password resets for everything else.
Use a unique password for every account. A password manager can generate and store these for you.
Turn on two-factor authentication wherever it is offered, especially on email, banking, and social media accounts.
Watch for phishing. Be skeptical of emails asking you to log in or confirm details, even if they appear to come from a service you use.
Check whether your email appears in this or other compilations.
There is no single company to notify in this case. Because the collection aggregates thousands of unrelated breaches, affected individuals should focus on their own account security rather than waiting for a notice from any one organization.
